Daily briefing · July 27, 2026

CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress Stacks

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

July 27, 2026 brings a clear ATTENTION verdict: two vulnerabilities are under active exploitation, one of which — CVE-2026-16812, a perfect CVSS 10.0 in VeloCloud Orchestrator On-Prem — was flagged by VulnCheck before CISA confirmed it, signaling real-world attacker activity ahead of official acknowledgment. The day saw 426 new CVEs published, 25 of them critical, with the VeloCloud flaw standing alone as a confirmed KEV entry. Beyond that anchor threat, a cluster of critical RCE and privilege-escalation bugs across TeamCity, WordPress plugins, pheditor, phpMyFAQ, and SiYuan demand immediate triage from defenders.

Today’s brief
  • CVE-2026-16812 (CVSS 10.0, KEV): VeloCloud Orchestrator On-Prem is being actively exploited — patch or isolate immediately.
  • TeamCity (CVE-2026-63077, CVSS 9.8): unauthenticated RCE via agent polling protocol affects all pre-2026.1.3/2025.11.7 instances.
  • Two pheditor critical flaws (CVE-2026-48030, CVE-2026-55579): hardcoded default credentials plus OS command injection equal trivial full server compromise.
  • Brazil faces a surge of ransomware hits across energy, healthcare, finance, and agriculture — Section9 and Global Secret Group are the most active groups this cycle.
25
critical
2
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-16812KEVCVSS 10affects VeloCloud Orchestrator On-Prem
A perfect CVSS 10.0 in VeloCloud Orchestrator On-Prem grants remote attackers unauthenticated access to privileged internal functionality, fully compromising confidentiality, integrity, and availability of the orchestrator and all managed data. Confirmed in both CISA KEV and VulnCheck KEV — the VulnCheck observation preceded official CISA confirmation, meaning exploitation was already occurring in the wild before the formal alert; this is the single most urgent patch of the day.
2
CVE-2026-59553◆ VulnCheckHIGH 7.1affects Product Feed Manager
An unauthenticated stored XSS in Product Feed Manager (≤7.6.1) was observed by VulnCheck before any CISA acknowledgment, indicating active attacker interest; exploitation can lead to session hijacking or malicious script injection against site administrators without requiring any credentials.
3
CVE-2026-48030CVSS 9.9PoCaffects pheditor
An OS command injection in pheditor's terminal action handler lets any authenticated user bypass the TERMINAL_COMMANDS whitelist by injecting shell metacharacters into the 'dir' POST parameter, achieving full remote code execution on the host — a proof-of-concept exists, lowering the bar for exploitation significantly.
4
CVE-2026-55579CVSS 9.8PoCaffects pheditor
Pheditor ships with a hardcoded default password ('admin') with no forced change on first login; any internet-exposed deployment retaining defaults gives attackers immediate full access to file editing, upload, and terminal features — the existence of a PoC makes mass scanning likely.
5
CVE-2026-63077CVSS 9.8affects TeamCity
JetBrains TeamCity before versions 2026.1.3 and 2025.11.7 allows unauthenticated remote code execution via the agent polling protocol — a critical exposure for any CI/CD pipeline exposed to untrusted networks, where compromise can cascade into the entire software supply chain.
6
CVE-2026-13714CVSS 9.8PoCaffects Realtyna Organic IDX plugin + WPL Real Estate
The Realtyna Organic IDX + WPL Real Estate WordPress plugin (before 5.3.0) allows unauthenticated PHP file upload due to hardcoded credentials identical across all installations, enabling direct remote code execution; every site running the default configuration is fully exposed to unauthenticated attackers.
7
CVE-2026-12394CVSS 9.8PoCaffects MemberGlut
MemberGlut (WordPress plugin before 1.1.5) fails to validate user roles during front-end registration, allowing any unauthenticated visitor to self-register as an administrator and achieve complete site takeover — a PoC is available, making automated exploitation straightforward.
8
CVE-2026-66398CVSS 9.4affects phpMyFAQ
phpMyFAQ before v4.1.6 lets authenticated administrators write arbitrary PHP files by manipulating an upgrade configuration setting and uploading a malicious ZIP, turning a legitimate admin workflow into a remote code execution vector — relevant in environments where admin accounts may be shared or phished.
9
CVE-2026-66395CVSS 9.4affects siyuan
SiYuan desktop (before v3.7.2) is vulnerable to reflected XSS via a crafted siyuan:// deep link in the bazaar plugin readme handler; because the Electron renderer runs with full Node.js access, successful exploitation translates to arbitrary code execution on the victim's desktop — a particularly dangerous vector for knowledge-worker environments.
10
CVE-2026-66396CVSS 9.3affects siyuan
A stored XSS in SiYuan (before v3.7.2) allows users with editor permissions to inject unescaped onload handlers into Gallery and Kanban cover images, executing arbitrary code in the Electron renderer with full Node.js access when any user opens the affected document — a stealthy persistence and lateral-movement risk in collaborative note-taking environments.
Ransomware today

Brazil is the focal point of ransomware activity in this reporting period, with Section9 emerging as the most prolific group, striking targets across financial services, technology, agriculture, and other sectors. Global Secret Group claimed Sinop Energia (energy and utilities) and SPDM (healthcare), while arcusmedia hit Power Moendas and the blackwater group targeted msgas.com.br in the energy sector. Over the past 30 days, lockbit5 (49 BR victims), lockbit3 (39), and ransomhub (35) lead the broader ransomware landscape, with arcusmedia and thegentlemen each accounting for 20 Brazilian victims.

********.com.br BRSection9
Sinop Energia BRGlobal Secret Group · Energy & Utilities
*****.ind.br BRSection9 · Agriculture and Food Production
*****.com.br BRSection9 · Financial Services
****.com.br BRSection9 · Technology
******.net.br BRSection9 · Financial Services
******.com.br BRSection9 · Other
SPDM BRGlobal Secret Group · Healthcare
Power Moendas BRarcusmedia · Other
msgas.com.br BRblackwater · Energy & Utilities
lockbit5 49lockbit3 39ransomhub 35arcusmedia 20thegentlemen 208base 20
Active groups & APTs

Several threat actor groups are currently being tracked with updated activity profiles, including againstthewest, apt73, kazu, kelvinsecurity, krybit, and coinbasecartel. While no confirmed victim counts are attributed to these actors at this time, their active monitoring status suggests operational readiness or reconnaissance phases that defenders — particularly in targeted sectors — should treat as elevated background risk.

Brazil focus

Brazil is experiencing a concentrated ransomware campaign wave, with Section9 hitting at least seven Brazilian organizations recently across financial services, technology, agriculture, and other sectors, and Global Secret Group targeting critical infrastructure (Sinop Energia) and healthcare (SPDM). The breadth of sectors — from energy to finance to food production — reflects an indiscriminate targeting posture that increases exposure risk for virtually any mid-to-large Brazilian organization regardless of industry.

******.net.brSection9 · Financial Services
******.com.brSection9 · Other
Sinop EnergiaGlobal Secret Group · Energy & Utilities
****.com.brSection9 · Technology
*****.com.brSection9 · Financial Services
*****.ind.brSection9 · Agriculture and Food Production
********.com.brSection9
SPDMGlobal Secret Group · Healthcare
Today’s recommendation: Organizations running VeloCloud Orchestrator On-Prem must apply the available patch or restrict external access immediately, as active exploitation is confirmed; simultaneously, teams should audit all TeamCity instances, WordPress plugin versions (particularly pheditor, Realtyna, and MemberGlut), and SiYuan desktop deployments for the critical flaws disclosed today. Given the number of hardcoded-credential and default-password issues in this batch, a sweep for factory-default configurations across all public-facing services is strongly advised.
With active exploitation already underway on a CVSS 10.0 vulnerability and a wave of critical RCE flaws published in a single day, now is the moment to validate which of these affected components actually exist in your environment — because attackers are already asking the same question.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share